Summary
In order for the Check Point MDR team to monitor your logs from your Check Point environment, we will require integration with your Management server. We connect to the Management API (available in R81 and higher releases) in order to request Alerts to ingest.
If you need any assistance with this procedure, please create a ticket in the MDR Portal in the "MDR Support" section or if you are currently Onboarding, reply to your Welcome Email, and we will assist you in a timely manner.
For Onsite based Management Start here
For Cloud based Management Start here
Onsite Management:
Note: We will need these two items filled in on the Quantum Smart-1 integration in the MDR Profile section of your MDR Portal. You will also need to ensure the procedure outlined below is completed before adding:
- Client Secret (API Key)
- Client URL (Public Management IP)
Procedure
Create and Authorize API Key
- Log into the Check Point Management server in Smart Console
- Navigate to: Manage and Settings > Blades > Management API > Advanced Settings > Set to “All IP addresses that can be used for GUI Clients” and click Ok.
- Navigate to: Permissions and Administrators > Trusted Clients > Click New at the top to add IP
- Add a separate Client for each of the IP’s listed below:
- Name: Check Point MDR
-
Addresses:
- 3.13.200.75
- 3.129.80.210
- 3.130.105.153
- 3.130.218.157
- 3.139.112.208
- 13.58.102.105
- 18.116.182.107
- 18.221.166.80
- 18.222.19.228
- 18.223.142.133
-
- Navigate to: Permissions and Administrators > Administrators > Add New User
- Name: Check Point MDR
- Authentication Method: API Key
- Click Generate API Key and make note of this
- Permissions Profile = Read Only All
- Expiration: Never Expire
- Click Publish to save changes
- Go to CLI (Gateways and Servers > Right Click Manager > Actions > Open Shell) and enter “api restart”
- Enter “api status” to verify the port that the service is running on (Default Port: 443)
- If the port reported has a different value than the default 443, please make sure to include it in the Management URL. ex: https://mymanagement.ip:4434/
Create Access Rules
- Connect to Smart Dashboard and add rules to allow traffic to the Management Server from the internet on HTTPS (TCP/443)
- If no NAT exists for the management server and the management is on internal IP space, create a NAT that allows access from the internet
- Create host objects for the MDR IP listed above and add them to a group
- Allow access from the MDR IP group created above to the external IP for the management server
- Install Policy
- Install Database to all Management servers
- If there are other log servers that we will be pulling from, please log in to those and install the database to all management servers
*This is the End for On-Premises Management. Please see next section for Cloud
Cloud Management:
Note: We will need these two items filled in on the Quantum Smart-1 integration in the MDR Profile section of your MDR Portal. You will also need to ensure the procedure outlined below is completed before adding:
- Client Secret (API Key)
- Client URL (Collected at the end of the procedure below)
Procedure
Create and Authorize API Key
- Log in to your Check Point Portal
- Open the the Quantum Smart-1 Cloud section
- Click Settings> API & SmartConsole
- Copy the URL from the web request section to enter as the client URL on the MDR customer portal for the integration.
- Generate the Management API key above the web request structure.
*NOTE: this key will be a full access admin key, If you wish to create a "Read-Only" key please open a ticket with MDR Support (support@cpirt.io) to schedule a meeting* - Apply both the Key and web request URL to the Quantum Smart-1 integration in the Profile section of the MDR Portal.